 main menuhome
forums Show me new threads!
bookmarks
post article
view blogs
vault you must be level 2 to upload files to your vault
downloads you must be logged to access downloads
Rootkit Collection
A news back-end to implement RootKit news into your website is here or more advanced version here.
An XML/RSS feed that includes both NEWS and BLOGS for RootKit is here: XML/RSS.
Beta feed for replied posts here. feedback to admins not forums, we know about times being off...
|
ROOTKIT
Because the OS isn't enough!
|
Saturday July 31st |
| | Featured Article: Nostalgia: n00bk1t, an advanced ring3 rootkit in C by jeffosz | Cheating klister? By: joannaIn the last issue of 29a magazine (http://29a.host.sk), which was made available few days ago, PHIDE utility has been presented among other interesting things. This utility is very similar to fu rootkit, however: 1) it is only a userland binary, which access kernel memory through \Device\PhysicalMemory and more importantly 2) it is able to hide process in such a way that it is not detected by klister 0.3 and older versions! However PHIDE does not bypass the general technique of process detection based on reading dispatcher database, but rather it makes use of the implementation mistake in this specific tool, klister, which naively assumes that process' PIDs will be unique in the system. PHIDE actually fakes the PIDs of the hidden process. New klister, version 0.4, which is now available on rootkit.com, fixes this mistake, and is now able to detect all process hidden also by PHIDE. A few words should be also said about the klister development status, since some people asks about new features to be added to this tool. Well, the klister is only a proof-of-concept tool, and is intended only to show that it is possible for Host based IDS systems to catch hidden processes. The full source code is available in hope that it can be useful for the community. I have recently developed the tool based on the similar concept, but unfortunately cannot publish the code since it was a commercial work. That is why it is rather unlikely that I will publish new klister versions in the near future. Sorry guys. Anyway, I encourage everybody to find new ways of klister cheating, and I will always try to update it, so that it will still be a useful proof-of-concept tool. joanna.
|
| |
ROOTKITS, Subverting the Windows Kernel
By: Greg Hoglund and Jamie Butler
Rootkits are powerful tools to compromise computer systems without detection. Get the original and best book on the subject here.
|
active for last 5 minutes
registered users:79912
There are currently 0 registered users and 22 guests browsing the website.
Welcome our latest registered user: Pris
| Jul 31, 12:06 |
| May 09, 04:30 |
| May 08, 15:33 |
| May 04, 15:42 |
| May 02, 03:59 |
| Best Screenshots / Analog |
| the most active news users |
based on the number of news posts for last 30 days
|